Urgent Security Vulnerability Detected in WhatsUp Gold – Take Action Now
An urgent security vulnerability affecting Progress Software WhatsUp Gold is currently being exploited, making it imperative for users to promptly install the latest patch.
The specific vulnerability is CVE-2024-4885 (CVSS score: 9.8), a critical remote code execution flaw impacting older versions of the network monitoring tool released before 2023.1.3.
“The WhatsUp.ExportUtilities.Export.GetFileWithoutZip functionality permits command execution with iisapppoolnmconsole privileges,” the company announced in a bulletin published in late June 2024.
As per findings by security analyst Sina Kheirkhah from the Summoning Team, the security flaw exists in the implementation of the GetFileWithoutZip method, which lacks proper validation of user-provided paths prior to execution.
An attacker could exploit this loophole to run code within the service account context. Kheirkhah has since published a proof-of-concept (PoC) exploit for this.
The Shadowserver Foundation reported that exploitation activities related to the vulnerability have been occurring since August 1, 2024. “From Aug 1st onwards, we have witnessed /NmAPI/RecurringReport CVE-2024-4885 exploitation callbacks (currently from 6 source IPs),” it revealed in a post on X.
WhatsUp Gold version 2023.1.3 rectifies two other severe vulnerabilities CVE-2024-4883 and CVE-2024-4884 (CVSS scores: 9.8), both allowing unauthenticated remote code execution through NmApi.exe and Apm.UI.Areas.APM.Controllers.CommunityController, respectively.

Also patched by Progress Software is a significant privilege escalation vulnerability (CVE-2024-5009, CVSS score: 8.4) that allows local attackers to boost their permissions on impacted systems by utilizing the SetAdminPassword function.
Given the trend of threat actors exploiting Progress Software vulnerabilities for malicious intents, it is crucial for administrators to install the latest security patches and restrict traffic to trusted IP addresses to mitigate potential risks.

